CVE-2015-1949: Command Injection
Published Jun 30, 2015
·Updated
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.
Affected Software
11 affected components
IBM Tivoli Storage Manager FastBack=6.1.0.0
IBM Tivoli Storage Manager FastBack=6.1.1.0
IBM Tivoli Storage Manager FastBack=6.1.7.2
IBM Tivoli Storage Manager FastBack=6.1.8.0
IBM Tivoli Storage Manager FastBack=6.1.8.1
IBM Tivoli Storage Manager FastBack=6.1.9.0
IBM Tivoli Storage Manager FastBack=6.1.9.1
IBM Tivoli Storage Manager FastBack=6.1.10.0
IBM Tivoli Storage Manager FastBack=6.1.10.1
IBM Tivoli Storage Manager FastBack=6.1.11.0
IBM Tivoli Storage Manager FastBack=6.1.11.1
Event History
Jun 30, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1949?
CVE-2015-1949 has a high severity rating due to the potential for remote command execution with SYSTEM privileges.
2
How do I fix CVE-2015-1949?
To fix CVE-2015-1949, upgrade IBM Tivoli Storage Manager FastBack to version 6.1.12 or later.
3
What is affected by CVE-2015-1949?
CVE-2015-1949 affects multiple versions of IBM Tivoli Storage Manager FastBack before 6.1.12.
4
Can CVE-2015-1949 be exploited remotely?
Yes, CVE-2015-1949 can be exploited remotely by attackers to execute arbitrary commands.
5
What type of vulnerability is CVE-2015-1949?
CVE-2015-1949 is classified as a remote code execution vulnerability.